CVE-2024-23350: Reachable Assertion in Multi Mode Call Processor
Permanent DOS when DL NAS transport receives multiple payloads such that one payload contains SOR container whose integrity check has failed, and the other is LPP where UE needs to send status message to network.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-23350?
CVE-2024-23350 is classified as a Permanent Denial of Service (DOS) vulnerability.
How do I fix CVE-2024-23350?
To address CVE-2024-23350, ensure updating to the latest firmware versions provided by Qualcomm or Google that include patches for this vulnerability.
Which products are affected by CVE-2024-23350?
CVE-2024-23350 affects various Qualcomm firmware products including WSA8845, WSA8840, WCD9395, and Android systems.
What type of attack can exploit CVE-2024-23350?
CVE-2024-23350 can be exploited through malicious payloads sent via DL NAS transport.
Is there any known exploit for CVE-2024-23350?
As of now, there have been reports of exploitation of CVE-2024-23350, resulting in active attacks leveraging this vulnerability.